{"version":"0.1","company":{"name":"YubHub","url":"https://yubhub.co","jobsUrl":"https://yubhub.co/jobs/title/senior-aem-devsecops-engineer"},"x-facet":{"type":"title","slug":"senior-aem-devsecops-engineer","display":"Senior Aem Devsecops Engineer","count":1},"x-feed-size-limit":100,"x-feed-sort":"enriched_at desc","x-feed-notice":"This feed contains at most 100 jobs (the most recently enriched). For the full corpus, use the paginated /stats/by-facet endpoint or /search.","x-generator":"yubhub-xml-generator","x-rights":"Free to redistribute with attribution: \"Data by YubHub (https://yubhub.co)\"","x-schema":"Each entry in `jobs` follows https://schema.org/JobPosting. YubHub-native raw fields carry `x-` prefix.","jobs":[{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_affa7659-e53"},"title":"Senior AEM DevSecOps Engineer","description":"<p>Secure Every Identity, from AI to Human</p>\n<p>Identity is the key to unlocking the potential of AI. As an AEM DevSecOps Engineer at Okta, you will oversee and automate our AEM infrastructure with a primary focus on security, reliability, and automated compliance.</p>\n<p>Key Responsibilities:</p>\n<ul>\n<li>Identity &amp; Access Management: Configure and manage Auth0 integrations for AEM, including token validation, OIDC/SAML configurations, and custom login modules to ensure secure user authentication.</li>\n</ul>\n<ul>\n<li>Headless Security: Oversee the security of AEM Headless deployments, including protecting GraphQL endpoints, managing CORS policies, and ensuring secure communication for decoupled front-end frameworks (React/Angular).</li>\n</ul>\n<ul>\n<li>Edge &amp; CDN Protection: Manage and configure CDN (e.g., Cloudflare, Akamai, or Adobe-managed CDN) to optimize performance and implement DDoS mitigation strategies.</li>\n</ul>\n<ul>\n<li>Traffic Filtering: Implement and maintain Traffic Filter Rules and Web Application Firewall (WAF) configurations at the CDN level to block malicious spikes and sophisticated application-layer attacks.</li>\n</ul>\n<ul>\n<li>Automated Security Scanning: Integrate security tools (SAST/DAST) and secrets detection into CI/CD pipelines (Jenkins, GitLab) to identify vulnerabilities early in the development cycle.</li>\n</ul>\n<ul>\n<li>Environment Hardening: Install and manage AEM author, publish, and dispatcher instances with a focus on Dispatcher security hardening, SSL certificate automation, and ModSecurity configurations.</li>\n</ul>\n<ul>\n<li>Observability &amp; Incident Response: Monitor system performance and security logs using tools like Splunk or New Relic to proactively address threats and performance bottlenecks.</li>\n</ul>\n<ul>\n<li>Compliance Auditing: Regularly audit the platform and its integrations (Adobe Analytics, Target) to ensure alignment with corporate security policies and industry standards.</li>\n</ul>\n<p>Required Skills &amp; Experience:</p>\n<ul>\n<li>Experience: 5+ years in administering and securing AEM environments.</li>\n</ul>\n<ul>\n<li>Identity Services: Proven experience integrating Auth0 or similar Identity Providers (IdP) for enterprise-scale authentication.</li>\n</ul>\n<ul>\n<li>Architectural Knowledge: Strong understanding of Headless CMS security best practices, including API key management and JWT authentication.</li>\n</ul>\n<ul>\n<li>Network Security: Expertise in managing CDNs and implementing DDoS mitigation and WAF rules.</li>\n</ul>\n<ul>\n<li>Technical Stack: Proficiency in Apache Sling, JCR, OSGi, and web servers like Nginx or Apache.</li>\n</ul>\n<ul>\n<li>Automation: Hands-on experience with scripting (Python) and CI/CD tools (Jenkins, CircleCI) to automate security and deployment workflows.</li>\n</ul>\n<ul>\n<li>Cloud Experience: Experience with cloud-based AEM implementations, such as AEM as a Cloud Service (AEMaaCS) or AWS/Azure.</li>\n</ul>\n<ul>\n<li>Diagnostic Skills: Proficiency in analyzing log files, thread dumps, and heap dumps to resolve security incidents or performance outages.</li>\n</ul>\n<p>The Okta Experience</p>\n<ul>\n<li>Supporting Your Well-Being</li>\n</ul>\n<ul>\n<li>Driving Social Impact</li>\n</ul>\n<ul>\n<li>Developing Talent and Fostering Connection + Community</li>\n</ul>\n<p>We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_affa7659-e53","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Okta","sameAs":"https://www.okta.com/","logo":"https://logos.yubhub.co/okta.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/okta/jobs/7688701","x-work-arrangement":"remote","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["Experience in administering and securing AEM environments","Identity Services: Proven experience integrating Auth0 or similar Identity Providers (IdP) for enterprise-scale authentication","Architectural Knowledge: Strong understanding of Headless CMS security best practices, including API key management and JWT authentication","Network Security: Expertise in managing CDNs and implementing DDoS mitigation and WAF rules","Technical Stack: Proficiency in Apache Sling, JCR, OSGi, and web servers like Nginx or Apache"],"x-skills-preferred":[],"datePosted":"2026-04-18T15:45:10.099Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Poland"}},"jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Experience in administering and securing AEM environments, Identity Services: Proven experience integrating Auth0 or similar Identity Providers (IdP) for enterprise-scale authentication, Architectural Knowledge: Strong understanding of Headless CMS security best practices, including API key management and JWT authentication, Network Security: Expertise in managing CDNs and implementing DDoS mitigation and WAF rules, Technical Stack: Proficiency in Apache Sling, JCR, OSGi, and web servers like Nginx or Apache"}]}